W32/Agobot-NX is an IRC backdoor Trojan and network worm. W32/Agobot-NX is capable of spreading to computers on the local network protected by weak passwords.

When first run, W32/Agobot-NX copies itself to the Windows system folder as bmsvc32.exe. W32/Agobot-NX runs continuously in the background providing backdoor access to the computer through IRC channels.

W32/Agobot-NX attempts to terminate and disable various anti-virus and security related programs and modifies the HOSTS file located at %WINDOWS%\System32\Drivers\etc\HOSTS, mapping selected anti-virus websites to the loop-back address 127.0.0.1 in an attempt to prevent access to these sites.